CVE-2023-28586: Improper Restriction of Operation within the Bounds of a Memory Buffer in TZ Secure OS
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28586.
What is the title of the vulnerability?
The title of the vulnerability is 'Improper Restriction of Operation within the Bounds of a Memory Buffer in TZ Secure OS'.
What is the description of the vulnerability?
The vulnerability leads to information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.
Which software is affected by this vulnerability?
Google Android is affected by this vulnerability.
What is the severity of CVE-2023-28586?
The severity of CVE-2023-28586 is high with a severity value of 6.
Where can I find more information about CVE-2023-28586?
You can find more information about CVE-2023-28586 in the following references: [Android Security Bulletin - December 2023](https://source.android.com/docs/security/bulletin/2023-12-01/#asterisk) and [Qualcomm Product Security Bulletins - December 2023](https://www.qualcomm.com/company/product-security/bulletins/december-2023-bulletin).